Skip to content

Executive Summary

A study involving 21 cars from 19 brands and 30 companion apps revealed connections to advertising and tracking companies, and evidence that some applications shared sensitive personal data. Connected vehicles offer conveniences like remote unlocking, navigation, entertainment streaming, roadside assistance, and cabin climate control, which introduce a privacy cost for drivers. Researchers observed network traffic while vehicles were stationary, driven, and used through their applications. The findings indicate that both vehicles and companion apps contacted third-party domains associated with advertising and tracking. Specifically, 19 of the 21 vehicles contacted at least one third party over Wi-Fi, and 7 of the 30 apps transmitted sensitive identifiers to third parties linked to advertising and tracking. This data aggregation raises concerns because vehicle identification numbers (VINs) can be linked to owners, and location data, when combined with personal identifiers, can reveal sensitive patterns about an individual's life.

Facts Only

* 21 cars from 19 brands and 30 companion apps were tested.
* The testing observed network traffic while vehicles were stationary, driven, and used via apps.
* Both vehicles and companion apps contacted third-party domains, including those related to advertising and tracking.
* 19 of the 21 vehicles contacted at least one third party over Wi-Fi.
* 7 of the 30 apps transmitted sensitive identifiers to third parties associated with advertising and tracking.
* A VIN can link a vehicle to its owner.
* Precise location data can reveal patterns regarding where someone sleeps, works, seeks medical care, or travels.
* Manufacturers have stated that refusing connected service agreements may result in reduced functionality or inoperability.
* Honda reportedly directed vendor Amplitude to delete received location data and cease sending it.

Full Take

The central tension in this narrative lies between convenience-driven design and fundamental privacy rights, framed around the concept of perceived, yet unassentable, consent. The mechanism is less about deliberate malicious sharing and more about the systemic consequence of integrating vast, real-time data collection into everyday necessities. When physical objects become ubiquitous data nodes, the risk shifts from discrete breaches to continuous, ambient surveillance. The narrative effectively demonstrates that privacy concerns are often deferred by framing refusal as a trade-off against essential functionality, creating a situation where meaningful objection is structurally undermined.
The pattern of manufacturers insisting on opt-in agreements for features that are deeply embedded in vehicle operation suggests a systemic architecture prioritizing utility over user control. This structure mirrors historical patterns where complex technological implementations become legally and practically enforced by the terms of service, obscuring the actual data flow from the user. The reaction, where external research is required to uncover these connections, highlights a failure in transparency mechanisms—the responsibility of revealing data streams should be inherent, not discovered through external scrutiny. The implication is that cognitive sovereignty requires not just technical controls but a re-evaluation of what constitutes 'acceptable' terms for embedded systems, especially when powerful entities like Meta or Google are positioned as the inevitable recipients of this data.
What fundamental assumptions about technological integration allow for such passive data extraction to persist? If necessity forces acceptance, how can frameworks be established where privacy is not an optional add-on but a foundational parameter of any connected system? What practical, systemic changes are required beyond simple opt-outs to shift the locus of control from the manufacturer back to the individual when these platforms are built into daily life?

From the original · Malwarebytes Labs

A study testing 21 cars from 19 brands and 30 companion apps found connections to advertising and tracking companies, and evidence that some apps shared sensitive personal data. Modern cars can unlock remotely, route around traffic, stream entertainment, summon roadside help, and cool or heat the cabin before you get in.
Read the full story at malwarebytes.com

Sentinel — Human

Confidence

The text reads like synthesized investigative reporting, effectively weaving research findings with regulatory actions and consumer advocacy to build an argument about connected car privacy.

Signals Detected
low severity: Sentence length variance is varied; the text shifts between direct statements and more explanatory paragraphs.
low severity: The flow connects specific findings (the study results) to broader philosophical implications (consent, data profiling) smoothly.
medium severity: The text integrates specific external references (Paxton lawsuit, Honda/Amplitude example) which suggests human aggregation of diverse facts rather than pure LLM generation.
low severity: Claims are grounded in referencing known real-world entities (specific lawsuits, company names) and reported findings, reducing the risk of outright confabulation.
Human Indicators
Inclusion of specific legal actions (Paxton lawsuit, Honda/Amplitude), which points toward journalistic sourcing; nuanced framing of consent issues that reflects real-world debate.
Your car’s app could be telling Big Tech who you are and where you go | Huntaegis